CryptoBoost AI

What permissions does CryptoBoost get on your Hyperliquid wallet?

When you connect Hyperliquid, you let the bot trade for you. You do not give it your money. Here is what that permission covers, what it cannot do, and how to switch it off.

[ Security ] Published 5 min read

How the connection works

Hyperliquid has a built-in way for trading tools to act on an account without holding it. It is called an API wallet. When you connect CryptoBoost, you:

  1. Sign one approval with your own wallet. This authorises a new API wallet address to trade for your Hyperliquid account. You never share your private key or seed phrase.
  2. CryptoBoost uses the API wallet to sign orders. Hyperliquid checks that the API wallet is approved for your account, then executes the order in your account.
  3. Everything settles in your account. Positions, margin and profit stay in your Hyperliquid balance the whole time.

The approval is recorded on Hyperliquid itself, not just on our servers, so you can see it and remove it from Hyperliquid directly.

What the bot can and cannot do

The bot can

  • Open and close positions
  • Place, modify and cancel orders
  • Adjust leverage and margin on positions

The bot can never

  • Withdraw funds from Hyperliquid
  • Transfer or send funds to any address
  • Approve other wallets or change your account ownership
  • Stop you from revoking its access

The "can never" column is enforced by Hyperliquid, not by a promise from us. Withdrawals and transfers need a signature from your own wallet, and the API wallet cannot produce one.

What the permission does not limit

Here is the full picture. A Hyperliquid API wallet is a trading permission, and Hyperliquid does not restrict it to one market. CryptoBoost's software trades only BTC perpetuals (BTC-PERP), but that is a rule in our system, not a limit enforced by Hyperliquid.

So the worst case is not "funds stolen". It is unwanted trading on your account. If you ever see activity you don't expect, revoke the API wallet and all trading stops at once. Your balance stays where it is.

To limit how much capital the bot can use, keep only your intended allocation in the account connected to CryptoBoost.

How to check and revoke access

You can switch the bot off from either side:

  • In CryptoBoost: pause or disconnect the bot from your dashboard at app.cryptoboost.trade.
  • In Hyperliquid: open the API page in the Hyperliquid app to see every API wallet authorised for your account, and remove the CryptoBoost one. After that, Hyperliquid rejects any order it signs.

Revoking does not close your open positions. Those stay in your account for you to manage.

Verify it yourself

Every order the bot places is a normal Hyperliquid order in your account. You can see it in your Hyperliquid trade history and on the public explorer. Nothing about the record depends on trusting CryptoBoost.

Common questions

Do I give CryptoBoost my private key or seed phrase?

No. You never share your private key or seed phrase. You sign a single approval with your own wallet that authorises a separate API wallet to place trades for your account.

Can CryptoBoost withdraw my funds?

No. On Hyperliquid, withdrawals and transfers must be signed by your own wallet. An API wallet cannot sign them, so the bot has no way to move money out of your account.

What happens if CryptoBoost's servers are compromised?

An attacker holding the API wallet key still could not withdraw or transfer your funds. The realistic risk is unwanted trading on your account, which you can stop at once by revoking the API wallet.

Do I need to approve every trade?

No. The one-time approval lets the bot trade automatically. You keep full control and can revoke the permission at any time.

Keep your keys.
Let the bot trade.

Activate your AI →

Perpetual futures carry substantial risk of loss · This article is general information, not financial advice